CVE-2026-22849 | Saleor up to 3.20.107/3.21.42/3.22.26 Refresh Token cross site scripting (GHSA-8jcj-r5g2-qrpv / EUVD-2026-3777)
A vulnerability was found in Saleor up to 3.20.107/3.21.42/3.22.26. It has been declared as problematic. The impacted element is an unknown function of the component Refresh Token Handler. Executing a manipulation can lead to improper neutralization of script in attributes in a web page.
This vulnerability is registered as CVE-2026-22849. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.